Inside a telecom security assessment: methods and tooling for mobile networks
15
1:00 PM - 2:00 PM
Security assessments on mobile networks are not generic IT penetration tests. The protocols, the interfaces and the failure modes are specific to telecom, and so are the methods and the tooling needed to test them properly.
In this session, Martin Kacer walks through how a telecom security assessment is actually run: how scope is defined across signaling, core and access, which techniques apply where, and which tools do the work at each stage.
Key topics include:
- How a mobile network assessment is scoped and structured
- - Methods that apply across SS7, Diameter, GTP and 5G SBA
- - The tooling used to capture, analyse and validate findings
- - Turning raw findings into remediation an operator can act on
Speaker
Martin Kacer
Security Researcher
Martin Kacer is a Security Researcher. He made several key contributions to GSMA security guidelines related to interconnect signalling of mobile networks and was a member of the GSMA FASG working group calling for the 5G interconnect security. He is the author of open-source Signalling firewall and was designing the telecom signalling threat intelligence, IDS-es, signalling vulnerability scanners, fraud detection, and in the past developing network elements and signalling probes. He conducted many security missions such as pentests and security audits in the Telecom domain.
15
1:00 PM - 2:00 PM